Concrete signature match: Trojan - Appears legitimate but performs malicious actions for W97M platform, family Valyria
Trojan:W97M/Valyria is a malicious macro embedded within Microsoft Office documents, typically delivered via spam email. When the user enables macros, the trojan executes to download and install more dangerous secondary payloads, such as ransomware or banking trojans.
No detailed analysis available from definition files.
28de2ccff30a4f198670b66b6f9a0ce5f5f9b7f889c2f5e6a4e365dea1c89d53Isolate the affected host from the network immediately. Ensure the malicious document has been quarantined and run a full system scan for secondary infections. Investigate for further compromise and block Office macros from the internet via Group Policy.